Crypto-Token Provisioning for Secure Enterprise Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Distributed software systems over open networks face challenges in secure communication and authentication, particularly in enterprise networks, where providing unique digital certificates and keys to each system element is costly and time-consuming, and requires direct communication with a certificate authority, which can be insecure and impractical.

Innovation Solution

The use of generic crypto-tokens with unique identifiers and public/private key pairs, which are shipped with computational components and securely authenticated through a provisioning server, allowing for secure communication and identification without pre-association with specific components or networks, enabling secure installation and authentication without requiring direct communication with a certificate authority.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If direct communication with certificate authority is used for provisioning digital certificates, then authentication security is improved, but installation time and complexity increase

Engineering Contradiction:
Improveauthentication securityVSAvoidinstallation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-provisioning computational components with digital certificates and private keys during the manufacturing process, before deployment to the enterprise network. This eliminates the need for time-consuming post-installation certificate provisioning and direct communication with certificate authorities, while maintaining security through factory-controlled key generation and storage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a provisioning server as an intermediary that mediates between certificate authorities and computational components. The provisioning server receives certificates from authorities and distributes them to components without requiring direct component-authority communication, thereby reducing installation complexity and time while preserving authentication security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If unique digital certificates are provisioned to each system element, then authentication capability is improved, but provisioning cost and complexity increase

Engineering Contradiction:
Improveauthentication capabilityVSAvoidprovisioning complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling computational components to automatically generate their own private keys and receive corresponding certificates through the provisioning server without requiring manual intervention. This automation reduces provisioning complexity and eliminates the need for complex manual key management processes while ensuring each component has unique authentication credentials.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal provisioning system that can handle multiple computational components simultaneously through a single provisioning server. This multi-functional approach allows the system to provision certificates to various component types (media servers, gateways, etc.) using the same infrastructure, thereby reducing overall provisioning complexity despite the large number of components being secured.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If certificate requests are validated thoroughly, then security is improved, but provisioning time increases

Engineering Contradiction:
ImprovesecurityVSAvoidprovisioning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies preliminary action by performing security validations during the factory provisioning process rather than at deployment time. Certificate authorities validate and sign certificates in advance under controlled conditions, allowing thorough security checks to be completed before the component is installed in the enterprise network, thus maintaining security without delaying deployment.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses copying by having the provisioning server retrieve pre-validated certificates from certificate authorities and distribute them to computational components. This copying process preserves the security validations already performed by the authority while enabling rapid distribution to multiple components without repeating the time-consuming validation process for each individual component.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS7707405B1Secure installation activation
Publication Date: 2010.04.27 PULSELINK SYSTEMS LLC
  • US7707405B1 patent drawing
  • US7707405B1 patent drawing
  • US7707405B1 patent drawing

AI summary

A system 100 for providing credentials to a computational component in a distributed processing network is provided. The system 100 includes: (a) a plurality of crypto-tokens 150a-n, each crypto-token 150a-n comprising a unique identifier, optionally a digital certificate comprising a unique public key and the unique identifier, and a private key corresponding to the public key; (b) a provisioning system 100 comprising a certificate authority 104 operable to generate the plurality of crypto-tokens 150a-n; and (c) a computational component 128 comprising a drive operable to receive and communicate with a selected crypto-token 150. The computational component 128 uses the digital certificate and private key in any of the crypto-tokens 150a-n to establish a secured communication session with the provisioning system 100. Before the establishing operation, any of the plurality of crypto-tokens 150a-n can be engaged with the computational component 128 to establish the secure communication session.